Cybersecurity Engineer

Hrtx

Philippines

Hybrid

PHP 1,000,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work setup

Job summary

Hrtx in the Philippines is seeking a Senior SOC Engineer to lead threat detection, incident response, and continuous monitoring within a Security Operations Center.

You will develop SIEM rules, perform threat hunting and forensics, and collaborate with threat intel and engineering teams to enforce logging standards and regulatory requirements. The role also includes mentoring junior analysts and coordinating across cloud and on-prem environments in a hybrid setup.

Qualifications

  • Experience leading real-time monitoring, triage, and response to security incidents.
  • Ability to develop and tune SIEM detection rules and correlation logic.
  • Experience in threat hunting and forensic investigations using logs and network data.
  • Familiarity with regulatory standards (GLBA, FFIEC, PCI DSS) and compliance logging.

Responsibilities

  • Lead real-time monitoring, triage, and response to incidents across cloud and on-prem.
  • Develop SIEM detection rules, use cases, and correlation logic.
  • Perform threat hunting and forensic investigations.
  • Mentor junior SOC analysts and guide escalated investigations.
  • Collaborate with threat intel, engineering, and compliance teams.

Skills

Real-time monitoring
Incident response
Threat detection
SIEM tuning
Threat hunting
Forensic investigations
Log analysis

Tools

GCIH
GSOC
CISSP
CSA

Job description

Our client is seeking a highly skilled and experienced Senior SOC Engineer to lead threat detection, incident response, and continuous monitoring efforts within our Security Operations Center. This role is critical to maintaining the confidentiality, integrity, and availability of our systems and data, especially in a highly regulated financial environment. The ideal candidate will bring deep technical expertise, a proactive mindset, and a passion for defending against evolving cyber threats.

Key Responsibilities
  • Lead and coordinate real-time monitoring, triage, and response to security incidents across cloud and on-prem environments.
  • Develop and tune SIEM detection rules, use cases, and correlation logic to improve threat visibility.
  • Perform threat hunting and forensic investigations using logs, endpoint telemetry, and network data.
  • Collaborate with threat intelligence teams to integrate IOCs and TTPs into detection workflows.
  • Maintain and enhance SOC playbooks, runbooks, and incident response procedures.
  • Mentor junior SOC analysts and provide technical guidance during escalated incidents.
  • Work with engineering and infrastructure teams to implement security controls and logging standards.
  • Support compliance efforts (e.g., GLBA, FFIEC, PCI DSS) by ensuring logging, monitoring, and incident response capabilities meet regulatory requirements.
  • Participate in red/blue/purple team exercises and post-incident reviews.
Qualifications
  • Lead and coordinate real-time monitoring, triage, and response to security incidents across cloud and on-prem environments.
  • Develop and tune SIEM detection rules, use cases, and correlation logic to improve threat visibility.
  • Perform threat hunting and forensic investigations using logs, endpoint telemetry, and network data.
  • Collaborate with threat intelligence teams to integrate IOCs and TTPs into detection workflows.
  • Maintain and enhance SOC playbooks, runbooks, and incident response procedures.
  • Mentor junior SOC analysts and provide technical guidance during escalated incidents.
  • Work with engineering and infrastructure teams to implement security controls and logging standards.
  • Support compliance efforts (e.g., GLBA, FFIEC, PCI DSS) by ensuring logging, monitoring, and incident response capabilities meet regulatory requirements.
  • Participate in red/blue/purple team exercises and post-incident reviews.
Preferred Certifications
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Operations Certified (GSOC)
  • Certified Information Systems Security Professional (CISSP)
  • Certified SOC Analyst (CSA)

Work setup: Hybrid, 3x a week RTO

****FILIPINO CITIZEN ONLY residing in the Philippines***

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Operations Engineer
Cybersecurity Operations Engineer

RecruitNest Consulting • Taguig

On-site
PHP 1,200,000 - 1,800,000
Senior SOC Analyst
Senior SOC Analyst

Hammerjack Pty Ltd • Manila

On-site
PHP 900,000 - 1,300,000
SOC Analyst
SOC Analyst

Astute Cybersecurity • Cebu City

On-site
PHP 360,000 - 600,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

RecruitNest Consulting • Taguig

On-site
PHP 1,200,000 - 2,100,000
Cybersecurity Analyst
Cybersecurity Analyst

Bounty Fresh Food, Inc. • Taguig

Hybrid
PHP 700,000 - 1,100,000
Security Engineer
Security Engineer

MEC Networks Corporation • Quezon City

On-site
PHP 600,000 - 1,000,000
IT.Senior SOC Analyst
IT.Senior SOC Analyst

Citco Group of Companies • Makati

Hybrid
IT.Senior SOC Analyst
IT.Senior SOC Analyst

the citco group limited • Philippines

Hybrid
PHP 900,000 - 1,300,000
Vacation and health insurance
Security Engineer
Security Engineer

JetSon Manpower Agency • Manila

Hybrid
NSOC Analyst Tier 1
NSOC Analyst Tier 1

Centrics Networks • Cebu City

On-site
PHP 420,000 - 660,000